Skip to content

Guide 04 — Coverage Rollout (Per-Layer Onboarding)

How each layer of the estate gets monitored on the new platform. Work top to bottom — colo first (it's the gap list), then metro, then venues.

1. Proxmox cluster

  1. Create a read-only API token on the cluster (PVEAuditor role is enough).
  2. One Zabbix host object represents the cluster (agentless), templated with Proxmox VE by HTTP; token in host macros.
  3. LLD auto-discovers nodes and all VMs: CPU, memory, disk, VM up/down, cluster quorum, node status. This is hypervisor-level VM coverage for free — every VM gets basic monitoring without an agent.
  4. Each physical node is also a NetBox device (hypervisor role) with the Linux agent template for OS-level detail (disks, SMART via agent 2, network).

2. Ceph

  1. Enable the Ceph RESTful/mgr module and create a monitoring user per the template docs.
  2. Zabbix agent 2 on one or two monitor nodes with Ceph by Zabbix agent 2.
  3. Coverage: cluster health status, OSD up/in counts, per-pool usage and IOPS, capacity forecasting from trends.
  4. Key triggers: health WARN/ERR, OSD down, pool >80% full, capacity trend projected full within 90 days.

3. Physical SQL servers

  1. OS layer: Zabbix agent 2 (Linux or Windows template).
  2. DB layer: native template per flavour — MSSQL by ODBC, PostgreSQL by agent 2, or MySQL by Zabbix agent 2 — with a least-privilege monitoring account. (Open question in the spec: confirm flavour.)
  3. Coverage: connections, replication/AG state if clustered, long queries, backup age (agent item checking last-backup timestamp is worth adding).

4. OPNsense firewalls

  1. Install the os-zabbixagent plugin from the OPNsense plugin repo; agent template covers OS, states table, gateway status.
  2. SNMP for interface counters if preferred for uniformity with network kit.
  3. Monitor every venue VPN tunnel from here: tunnel up/down + throughput items, one per venue. These become the parents in the dependency tree (Guide 05).

5. MikroTik routers (venues + metro)

  1. Enable SNMPv3 estate-wide (scripted via RouterOS API/SSH across all devices — one credential set, stored as Zabbix secret macros).
  2. Official MikroTik by SNMP template: auto-detects model, discovers interfaces, CPU/mem, PSU/temp where supported.
  3. Venue routers are the anchor host per venue — their ICMP/SNMP reachability trigger is the parent for everything else in the venue.

6. Metro/core network kit

  1. SNMPv3 + vendor-appropriate templates. This replaces LibreNMS.
  2. Interface LLD with sensible filters (physical + uplinks yes; every VLAN SVI no) to keep item counts sane.
  3. Traffic/error/discard triggers on uplinks; topology dependencies per Guide 05.

7. UniFi switches and APs

  1. Enable SNMP in the UniFi controller (applies to all adopted devices).
  2. SNMP templates give per-device status, uplink traffic, basic radio stats.
  3. Supplement with HTTP checks against the controller API for what SNMP lacks: AP adoption state, client counts, firmware. (Open question: controller self-hosted vs cloud decides how this is queried.)
  4. Don't over-monitor APs — up/down, uplink, client count, and radio utilisation is the right level for 200 APs.

8. Tills (Windows, active agents)

  1. Scripted MSI install of Zabbix agent 2: msiexec /i zabbix_agent2.msi /qn SERVER=<zbx> SERVERACTIVE=<zbx> HOSTNAME=<netbox-name> TLSCONNECT=psk ... Hostname must match the NetBox device name (Guide 01 §4). Use PSK encryption — till traffic crosses the VPN.
  2. Deploy via whatever reaches tills today (RMM, GPO, or a USB-stick-and-checklist pilot venue first).
  3. Trimmed template (clone of Windows by Zabbix agent, active): agent availability (= till up), disk space, CPU/memory sustained, uptime (detects unexpected reboots and never-rebooted machines).
  4. Active mode means tills initiate the connection — zero central polling load and no inbound firewall rules at venues.

Onboarding verification per wave

After each wave: every synced host green (no unsupported items), data flowing on spot-checked items, triggers test-fired for one device per role, and the venue/metro dependency chain verified by a controlled test (Guide 05 §4).